Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
CopyKittens: Persistent Iranian Cyber Espionage Group
A profile of CopyKittens (G0052), an Iranian state-sponsored cyber espionage group targeting governments, defense, and IT sectors.
Threat Profile: Contagious Interview (G1052)
Contagious Interview (G1052) is a North Korea-aligned threat group focused on cyberespionage and financially motivated operations targeting developers and…
Confucius APT: Persistent Espionage in South Asia
Confucius APT is an India-linked cyber espionage group active since 2013, primarily targeting military, government, and high-profile individuals in South Asia…
Cobalt Group: A Relentless Financial Cybercrime Syndicate
A profile of the Cobalt Group (G0080), a highly sophisticated and persistent threat actor targeting financial institutions globally for illicit financial gain.
Cleaver (G0003): Iranian APT Targeting Critical Infrastructure
Cleaver (G0003) is an Iranian state-sponsored threat group notorious for espionage and sabotage against global critical infrastructure.
Cinnamon Tempest: The Espionage Group Cloaked in Ransomware
Cinnamon Tempest (G1021), a China-based threat group, uses ransomware as a smokescreen for cyberespionage and intellectual property theft.
Chimera (G0114): Enduring Espionage in High-Tech and Aviation
Chimera (G0114) is a suspected China-based APT group active since 2018, known for persistent cyber espionage targeting semiconductor intellectual property and…
Carbanak Threat Profile: Financial Apex Predators
A deep dive into Carbanak (G0008), a financially motivated cybercrime group known for sophisticated attacks against global financial institutions.
BRONZE BUTLER (G0060) Threat Profile: Persistent Chinese Cyber Espionage
A detailed profile of BRONZE BUTLER (G0060), a Chinese state-sponsored cyber espionage group primarily targeting Japanese organizations for intellectual…
Blue Mockingbird (G0108): Persistent Cryptomining Threat
Blue Mockingbird (G0108) is a financially motivated threat actor group focused on deploying Monero cryptocurrency miners on Windows systems.
BlackTech (G0098) Threat Profile: Chinese Cyber Espionage Group
An in-depth profile of BlackTech (G0098), a sophisticated Chinese state-sponsored cyber espionage group targeting government, military, and critical…
BlackOasis (G0063): A Persistent Cyber-Espionage Threat
BlackOasis (G0063) is a sophisticated Middle Eastern threat group known for cyber-espionage against high-profile targets using zero-day exploits and FinSpy…
No adversaries match your search.